The Worst Website in the Entire World
matduggan.com
matduggan.com
If you've ever wondered what the "Enterprise Application Server v21.5™ now with AI, Chatbots, LDAP, Active Directory Integration, Orchestration, and Web 3.0" experience looks like, this is it.
This is what happens when you bring enterprise software into the general public's view. This is what enterprise software customers see every day. Remember, at some point in the rollout of this dog, the team sat in a conference room and came to the right conclusion that the portal is terribly difficult to navigate, and thus the bright idea to write an 21 page PDF instruction manual for the portal was handed off to a 18 person team.
Edit update: The "Enterprise Chatbot Integration Plugin v2.1™ for Enterprise Portals - Enterprise Application Server v21.5" was an add on kicker for $1.6MM license revenue and $3.8MM for 21 years of support. This plugin was developed by one person who works for EnterpriseSoftwareCorp Inc at the behest of sales and marketing and management that decried "we must have a Chatbot AI offering for our enterprise customers because they are asking why we don't." The sales exec who inked the contract after the Broadcom merger ended up #4 in the company for sales, went to Hawaii for the EnterpriseSoftwareCorp President's club awards presentation. The Broadcom engineer who was forced to implement this plugin into the Portal just copied the example from the docs (a template of links) and realizes he'll really have to roll his own LLM to add any real capabilities to the bot. But, he was able to check the box that says "we have a chatbot"
Certainly my utility websites (e.g. electric/gas) are a lot more functional and a lot less user hostile, because...those companies would really like it if you paid your bill on time, so at least that workflow is pretty polished.
Oh gods, the painful flashbacks.
Over in the USA, setting up a bill autopay for a variable amount generally involves a credit card intermediary with a 2-4% rake or a lot of risk to you.
https://en.wikipedia.org/wiki/Direct_debit#United_Kingdom
Not only does it not cost anything to the payer, the "Direct Debit Guarantee" also protects the payer from mistakes and fraud.
This isn't a new system, it's over 50 years old.
Paying bills shouldn't be a risky or expensive thing to do.
I ran an Enterprise Apps org for a F500 where IT was purely a cost center and we created crap like this all the time.
Your utility websites are customer facing and everything that the user can't do themselves will result in a phone call or a ticket wich will directly drive up cost.
In enterprise it is the opposite. Whatever the costumer cant do themselves requires a ticket. Any ticket or fast ticket response requires support wich increases revenue.
I just had a meeting with someone from IBM last week about API Connect, they admit that their docs suck and are wrong in places. It is typical enterprise software, slow and cumbersome, just as reported by OP.
this make so much sense, but i never thought about it
you get one guy who just comes up with ideas in the shower and then drops a message on microsoft teams at 9:30pm telling the team to make it so, and you also have any manager even remotely involved with anybody who uses the product able to dictate features and functionality too, none of these people have experience in technical roles and are either sales, ex-sales or ex-scrum masters.
then finally at the end of the human centipede, you have a bunch of .NET-brained pseudoprogrammers sitting in a circle nitpicking and debating the most "correct" way to split up and size the current thing and then cram it into the existing mess until you end up with a plan of action that is a combination of multiple ideas which may have once been half decent in isolation but the result is a steaming pile of human shit.
In the current product I'm building, the domain experts are a generation older than myself and the mockups and designs they produce reflect that. If we just recreated their spec to the pixel, our application would fit right in on a Windows 95 desktop.
Yet if you were to look at our application, it has a clean, modern, user friendly design. To accomplish that required me to occasionally push back when they were set in their ways or some cases just ignoring the requirements and building out certain functionality my way. The domain is sufficiently complex that we don't have a ton of time to focus on UX. So the most important thing was setting the general UX patterns from day 1 and mandating developers follow that early on.
These words you are using, I do not think they mean what you think they mean ;)
As if any front end developer came up with this. Anyone who has ever had job in the industry knows this is straight from management.
What should the developer do exactly? Ignore the ticket? Educate the manager who’s perhaps three steps up in the hierarchy and doesn’t even know the person’s name who is charged with implementing the misfeature? Neither would go down well.
Also, the error he got when he tried to put in the password the first time is likely because there's a mismatch between what it claims the password rules are, and what they really are. He might have exceeded the maximum password size (yes, I know they're supposed to be salted in the backend, and maybe then even are, but you still run into this). Or it might be that he used disallowed punctuation (some sites seem to dislike anything other than question marks and the ones over the 1-2-3 keys... I've personally seen the percent sign and ampersand both cause problems.
If there were some little embedded xml file that my password manager could pull from the page automatically that would tell it what the rules are, then I wouldn't have to debug your shitty account creation systems, nameless developer drones out there working for big companies! Not that you care.
FTFY.
Anyway, somebody somewhere about a decade ago seems to have injected into the heads of such rule-makers that users who paste their password confirmations defeat the purpose of the confirmation mechanism, which was leading to excess support requests for forgotten passwords. So, therefore, pasting into the confirmation box (or even better, both boxes) should be disabled.
Never mind that password rules have gotten more complex, that allowing users to temporarily preview their passwords instead is now recommended, or that the use of password managers and online password resets means even if the original concern were valid, it's now moot. The rule exists, and so it must be followed.
At some point these corporations do lurch forward (or die), so eventually this will get changed, but it'll happen way slower than it should.
Prevent that, you stupid website, I dare you!
You can say no but management isn’t under any obligation to capitulate, and often won’t.
More over, it’s often solutioneering as a result to some other management identified issue that devs have pushed back on.
There was a period in the late-aughts when people wanted to emulate the iPhone's inertial scrolling on the desktop. Most modern sites had it and it was infuriating.
That's probably around the time when this site was built.
> Don't do this to me. I get to copy paste whatever I want whenever I want. When you get your own browser you can do whatever you want but while you are living in my house under my rules I get to copy/paste whenever I goddamn feel like it.
Forcing the user to type the password manually rather than letting them paste something in. I think the original idea was to not allow them to mistype the first one, then paste the typo in the second field. But it's a dated practice and very annoying.
I once worked on a project for a Pharma company and this one guy tried very hard to push his password requirements and no pasting stuff, but luckily we convinced someone with final say that we should just follow the NIST guidelines for password reqs and leave the UX of the password field up to the UX people lol.
I do agree though that smooth scrolling was a front end developer offense, luckily it went out of style pretty quickly.
correct. the other analysis here is wrong. we see similar for payments where user is not allowed to paste in ACH info.
but this isn’t exactly about user error per se. this is about support cost for bad entries. if the user types a wrong password during registration the recovery of such is very hard. the common user (even of a product like fusion) is VERY unsophisticated and will have severe problems recovering. the more advanced user will have plugins that disable paste disabling. the middle skill user (like in the post) will get past it on their own.
so net net this is just another case of this is why we can’t have nice things. they “have to” address that bottom (skill) level of users.
personally i can excuse this. the rest, not so much!
No one's going to risk their job over their boss's inane request to break copy & paste.
This edge is a greatly under-acknowledged and under-represented boundary of propriety, and is routinely flagrantly and hypocritically overrun by organizations with legions of attorneys who fight tooth and nail to stake their claims in the providence of others.
The close cousin is the "click-wrap" agreement, which should be the very first point of engagement for access to any resource that employs it, but is perennially represented as an afterthought which a priori deprives the visitor of recourse from his later exploitation using the form of a "contract" which is fully understood by everyone to not be read, is written in gibberish, and placed at the very end of a primrose path of necessity for access to one's own labors.
A huge warning sign of the intrinsic rentier dynamic of the high technology industry has been built into every PC since the dawn of the era and on prominent display: the "Welcome" screen. You think you are being warmly greeted upon arrival to the cusp of a vibrant commons, but you are actually being told in no uncertain terme that the PC you just bought was pre-appropriated by its software. The purchase price is rent. The device is your property only in the sense that you own the direct costs of its failure and disposal. You are given an account with limited access to its capabilities and being permitted to access it under the auspices of your hosts. Your work is without value to your hosts. The device is a conduit of your continuing consumption, controlled as tightly as possible, which with every step into its labyrinth further reduces, limits and degrades the value of your work to you, and shifts its value to the device purveyors.
This hazard is conventional to the structure of every web service today, including this one: your data (work) goes in and never comes out. It's trapped in the dynamic and context maintained by the host.
No social media architecture today respects your work in context, including this one.
Your comments should belong to you, be hosted by you, and maintained in a mutually shared and beneficial context. But instead your comments go into a black box which you are permitted to review, in exchange for locally issued currency called (tragically) "karma" which is a simply a mechanism for limiting your visibility within a hopelessly regressive and passé format of a reverse-chronologically ordered list of the popular. Everyone on the social web is a serf, tilling a text box, and sharecropping status.
My making an example of HN not to call it out for being egregious. HN is completely ordinary. I'm merely offering an example for how totally indoctrinated the technogentsia is to these dark patterns of social networking architecture and how blind everyone is to them.
It's pretty weird that these dark patterns are so pervasive when you consider that the ideological bent of most computer technologists is "libertarian".
But I should note that California ideology is inherently Randite, and Ayn Rand was a deeply disturbed person.
With transformer AI we have now seen that every human input on the web has specific economic value which is being aggregated and harvested towards the creation and consolidation of enormous kingdoms of social wealth and privilege. This is being done completely without regard for the principles of propriety that software and MSM content publishers have represented through law as being essential to the construction of a commonwealth.
Every output of a transformer is a derivative work without even attribution, much less royalties.
And the AI technologists seem poised to have transformers run interference at every level of "customer" interaction with new architectures.
The more you look into it, the more you will see that high technology has been an epic swindle to transfer control of a commons to narrow silos of exceptional privilege, in which not only does the commonwealth shrivel in exchange for the tech's very limited public advantages, but the vehicle you use for your contributions endlessly deprives you of the just fruits of your own labors, encircles you with infrastructure beyond your reckoning, and enforces your conformance to alien protocols via dark patterns.
Much as automobiles make every destination into a parking lot, so the web browser has made every avenue to knowledge end in a gate which is ever further obfuscated into an opportunity to withhold something of value from the visitor, including the value of your own work in context.
"Welcome."
Maybe.
Broadcom didn't make vmware desktop apps free because they want you to use them; they made them free because they don't want to sell or support them anymore. They only still exist because they have to ride out existing commercial support agreements and customers need the software while they transition their workflows.
Do not use Workstation or Fusion anymore; these products are dead-ended.
I run into it relatively frequently and it both angers me and blows my mind that some developer or team thought this made sense
Enter username, click, now enter password is revealed.
Some sites, password manager manages to do both even if only one is shown but usually not.
It’s a common known fact that every person is born with a certain max number of clicks and taps. We all only have so many clicks left in our lives, that’s one less click that I’ll be able to use doing what makes me happy like doom scrolling Twitter. Dammit.
Most common are the passwords that don’t allow certain characters which leaves me thinking: (1) they must have SQL injection bugs all over the app and (2) they probably aren’t hashing passwords. Either way it’s a clear confession of malpractice.
A weird one in that example is that you aren’t allowed to use any trigraph that appears in your email. I find it amusing because last month I was working on an application that has a large number of autocomplete boxes that start showing options when you enter the first three characters and I must have filled out the form hundreds or not thousands of times so I wrote a little Python script that would compute the trigraph frequencies for any set of names. I found out the most common trigraph in country names is “and” for instance.
Actually, one I've run into is web-framework-level security systems that are hard to disable. Stuff that prevents users from keying in, like XSS attacks. It's not that the password field is being used unsafely, it's that the web framework they're stuck on makes disabling security on a certain text field more complicated than it needs to be and telling the users "screw it, don't use this character in that password" is easier than figuring out how to get the Rube Goldberg machine to do what you actually want. Back-end languages aren't hot garbage like html+js+css so usually it's normal proper BCrypt in the back.
Obviously a modern web framework won't have this problem, but a lot of sites are old and still running on messy cobbled-together piles of JQuery.
It was trashing API keys and passwords which is a problem when "the customer can't log in". I didn't have a hard time disabling this behavior at all though. My feeling is that it is impossible to "live with it" because I didn't know exactly what rules I had to follow to not get strings corrupted.
More than a few times I've written properly sanitized and parameterized applications, and security came along after the fact and told me we had to prevent input of certain characters. Didn't matter that we handled it just fine, didn't matter that it was safe to put it in. Security's argument was that some other team, some where, at some future time might somehow reuse our data and not follow the same best practices.
So no special characters in your password because some engineer in the future might possibly introduce a bug.
But how does this logic work when a keylogger can basically do the same thing to a typed password?
Site: Please make a password
Human: 7#hs&_suiE2KcS0
Site: No copy and pasting
Human: mydogisagoodboy123
Site: Needs special characters
Human: Pa$$w0rd12345
Site: Looks great thanks
Anyone looking for work can probably empathize. All the other websites mentioned are distant runners up to that monstrosity.
For that matter, Peoplesoft isn't any better.
If it's anything like the "employment sector" options that banks ask you to pick from, then they're not trying to collect accurate info, but rather asking you to bucket yourself into a categorization system used by some very popular credit/risk-scoring heuristics.
My guess for why an HR platform is asking such a thing: it probably populates a field that can be fetched through an API, by corporate spending platforms (Float et al) that integrate with Workday, to determine (or at least "recommend") the employees who should be issued spend cards.
I was railing against workday for a different reason last week. I had a qualifying event and needed to add a dependent to my health insurance. The first screen in the flow was to change my coverage, but it only offered "self" plans (not the self + dependent I was trying to change to). I finally learned (after 2 screenshot laden emails with HR) that I had to "submit my choice and continue" for the wrong plan before I'd be allowed to choose the correct self + dependent plan on some future screen that I had no idea even existed. The "submit my choice and continue" felt rather final.
That was also the thesis from an article that made it to HN’s front page a week ago [2].
[1] https://www.businessinsider.com/everyone-hates-workday-human...
edit: downvotes? That's literally the situation here, look at the friggen URL.
instagram, but instead of infinite scroll you just show a blank canvas. When you post you include an xy position used to absolutely position it on the wall. Everything is 100x100 pixels max. Epoch time of post date determines zIndex.
But have you tried to actually perform a task? Ie "I want to buy an animal-shaped robot". Your eyes don't have anchor points in such a chaotic layout, it's very easy to get lost, miss items, and forget which items you already checked and which ones not. Users probably get a brain seizure after 1 minute trying to actually find a product.
A friend of mine told me that he apparently has a physical store as well, which has exactly the same vibe as the website.
* B * * B B * *Some interesting comments in the source:
<!--$sitebuilder version="2.9.0" extra="Java(1.8.0_231)" md5="58227db99c3a8f4ebd4480726328f28f"$-->
<!--$page size 3500, 2832$-->
I dread to think what garbage that is. Is it Yahoo SiteBuilder? https://www.youtube.com/watch?v=84zfRBcFb9IThis will prevent all websites detecting clipboard events and it defeats a lot of the annoying website behavior without needing to disable javascript entirely.
The only things it may break is if you legitimately do use any web apps that need to detect clipboard events; but, I have yet to run into anything.
It's me. I'd wear that shirt with a cat samurai on it.
First, the shirt is very easy to find. If you want it, you can easily find the store online with the information from the post alone.
Second, Instagram is chock full of shady sellers like this one selling t-shirts with AI-generated pictures. You can order from them and the product will probably arrive (eventually), but their websites are copy-pasted versions of each other (I just found at least six stores with identical "About Us" text) with different t-shirt designs whose reviews are uniformly poor. So don't count on excellent customer support.
Then again, maybe you are the type of person who always wanted to maybe receive a badly-printed, misaligned polyester shirt of a cat carrying a deformed sword. If that's the case then today is your lucky day.
Here's a copy of it [1]. Here's a video that explores it and talks about the person who probably designed it [2].
You won't get the full Yvette's experience on a modern browser and computer because even if your browser does automatically play the MIDI file that the site tries to send it will probably sound good because you've probable got a decent sound system with good MIDI instruments.
Reminds me of https://www.lingscars.com/ only even more so…
This broadcom website is a banal evil.
> Can you go stand in a mall and spend an afternoon getting people to test it?
Does that really work ? If a stranger at mall asks us to install a random app out of regular play store flow, only a small number of people will oblige. That number should ideally be zero.
Last example I witnessed: my home insurance forced me to re-register in their website due to some (clearly half-assed) migration. The way to force that was giving you a login form with user/password but no clickable "Submit/Login" button! And then a mini (like 50px tall) banner at the top of the page telling you that you had to recreate the account.
Good grief.
You can still have the same framework/layout. EG, support, products, etc. But you can do it under "categories". For example, "VMware by Broadcom" or some such blather.
And all support, all webpages, are only vmware related in that category.
But really, transitioning vmware's webpages to this is just dumb. What a waste of time. Just use vmware's website with a "by broadcom" in the banner, and who the hell cares.
So juvenile. That little bit of brand recoginition, oh it's so important.
Yeah, it's so important that it's not LSI, but broadcom in the firmware when my server boots now? Firmwares all need to have name changes?
And while I'm here... Thankfully, I am in a new job where I don't have to support vSphere anymore, but I just want to give a big "fuck you" to Broadcom for literally wiping the quite-decent community forums and knowledge base off the map. Sure, the KBs still exist, but on a different domain, and they deleted _all_ the metadata and the old KB links scattered across decades and the web all 404 now.
If Broadcom's goal was to reduce support costs, eliminating the forums and neutering the KB was a pretty bad way to go about it.
I hate that pattern because it's super confusing. Did I click the wrong link? Just tell me you can't find that page.
Many enterprise websites undergo so many retools that search engines trying to drop you off at a specific page would just 404 everything (even the main page if it's something like `example.com/main/en/index.php`), so the 404 redirect is "required". Then one company buys another, then all example.net/useful/docs links are translated to example.com/useful/docs links, which 404, which redirect to example.com's front page.
SEP was great because it was low impact and ticked a compliance checkbox. Useless if any event was going on but in the technical planning calls these clients just werent interested and would passively renew SEP every year like clockwork. Then broadcom switched up the website and every single one of them brought up the 'so we are wanting EDR after all' pitch request on their own. None of them could figure out how to renew their license.
edit: Have you guys seen IBM's fix pack site? it technically works, but jeeze. Why do I have to go through a web store ordering flow to patch db2?
And I hate Oracle's and Red Hat's paywalls, even if I can understand their presence.
Or should that be in a post about the best website?
I’m amazed by UTM (I know it’s “just” QEMU behind the scene, but they put a very good front on it).
Any company that blocks copy paste on their website is stupid and I hate them.
Don't give Google any ideas, err, wait...
<after looking> At least he didn't have to post a vacation request in SAP.
Part of their execution problems might be misleading metrics. Their "how was our service?" followup emails aren't sent for the routine (around 50%) fulfillment fudge-ups that backend should've prevented. Nor for occasional checkout breakage that fails with signs of multiple things that are simply being done incorrectly. So I have the nagging thought that someone might be hitting their KPIs/OKRs, and the right people aren't aware what a dumpster fire they're operating.
I wonder whether Amazon could've already eaten the online component of that category, with their overall superior competence and (selective) customer focus, if they didn't have the counterfeits indifference/misalignment problem, and worsening reputation for quality and caring about the customer.
https://www.vice.com/en/article/a3bwjj/the-cuck-centric-flam...
> Both [Maddox and his friend Kokkinos] performed at Upright Citizens Brigade in LA, sometimes together, with Kokkinos occasionally guesting on The Biggest Problem in the Universe*, a show Maddox co-hosted with his then friend Dick Masterson. After Masterson began dating one of Maddox's exes, creating an interpersonal rift that resulted in the duo cancelling their podcast in 2016, Masterson launched his own podcast, The Dick Show, on which Kokkinos was soon a frequent guest. As The Dick Show grew in popularity, Masterson and Maddox’s public rift widened, with each party’s respective fanbases joining in on the antagonism.
This one is funny!
If you know, you know.